TA482 is a likely Turkish state-aligned threat actor known for phishing campaigns targeting US journalists' social media accounts.
Analyst brief
TA482 is a threat actor likely aligned with the Turkish state. It primarily targets the social media accounts of US-based journalists and media organizations. Its main TTP involves credential harvesting through phishing campaigns, with infrastructure hosted on Turkish-origin services. Defenders should focus on anti-phishing measures, especially for journalists, and enforce multi-factor authentication.
TA482
unknown
Since early 2022, Proofpoint researchers have observed a prolific threat actor, tracked as TA482, regularly engaging in credential harvesting campaigns that target the social media accounts of mostly US-based journalists and media organizations. This victimology, TA482’s use of services originating from Turkey to host its domains and infrastructure, as well as Turkey’s history of leveraging social media to spread pro-President Recep Tayyip Erdogan and pro-Justice and Development Party (Turkey’s ruling party) propaganda support Proofpoint’s assessment that TA482 is aligned with the Turkish state.